Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.8 CVE-2024-22938 Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function… Bosscms No fix yet Fix from $1,9502024-01-30 HIGH 7.5 CVE-2024-23629 An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access prote… Mr2600 Firmware Mitigation only Fix from $1,9502024-01-26 MEDIUM 6.5 CVE-2023-35836 An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy of the network configuration… Pocket Wifi 3 Firmware after 3.009.03_20230504 Fix from $1,6002024-01-23 MEDIUM 5.3 CVE-2023-44401 The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `… Graphql 4.3.7 / 5.1.3+ Fix from $1,6002024-01-23 MEDIUM 6.5 CVE-2024-23675 In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST… Cloud 9.0.8 / 9.1.3+ Fix from $1,6002024-01-22 HIGH 7.5 CVE-2023-52111 Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity. Emui No fix yet Fix from $1,9502024-01-16 MEDIUM 5.3 CVE-2023-4812 An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all… GitLab 16.5.5 / 16.6.4+ Fix from $1,6002024-01-12 HIGH 8.8 CVE-2023-5356 Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all… GitLab 16.5.6 / 16.6.4+ Fix from $1,9502024-01-12 MEDIUM 5.5 CVE-2023-41994 A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view fro… macOS 14.0+ Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2024-21736 SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A functio… S\/4hana Finance Mitigation only Fix from $1,6002024-01-09 HIGH 7.2 CVE-2024-21735 SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization … Lt Replication Server Mitigation only Fix from $1,9502024-01-09 MEDIUM 5.5 CVE-2023-41779 There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user… Zxcloud Irai 7.23.32+ Fix from $1,6002024-01-03 CRITICAL 9.8 CVE-2023-52077 Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens … Nexkey 12.23q4.5+ Fix from $2,3002023-12-27 HIGH 7.6 CVE-2023-5644 The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view a… Wp Mail Log 1.1.3+ Fix from $1,9502023-12-26 HIGH 8.1 CVE-2023-49949 Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes. Passwork 6.2.0+ Fix from $1,9502023-12-26 HIGH 7.5 CVE-2022-39337 Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v… Hertzbeat 1.2.1+ Fix from $1,9502023-12-22 MEDIUM 6.3 CVE-2023-50732 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script w… Xwiki 14.10.7 / 15.2+ Fix from $1,6002023-12-21 MEDIUM 5.3 CVE-2023-50705 An attacker could create malicious requests to obtain sensitive information about the web server. Uc 500e Firmware No fix yet Fix from $1,6002023-12-20 MEDIUM 6.5 CVE-2023-49734 An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the… Superset 2.1.2 / 3.0.2+ Fix from $1,6002023-12-19 MEDIUM 6.8 CVE-2023-6355 Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug. T… Controller 7000 Firmware 8.70.231204a / 8.80.231204a+ Fix from $1,6002023-12-18 HIGH 8.2 CVE-2023-41314 The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Plea… Doris 2.0.3+ Fix from $1,9502023-12-18 HIGH 8.2 CVE-2023-6837 Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to ha… Api Manager 2.5.0.32 / 2.6.0.52+ Fix from $1,9502023-12-15 HIGH 8.8 CVE-2023-45185 IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper author… I Access Client Solutions 1.1.9.4+ Fix from $1,9502023-12-14 HIGH 8.1 CVE-2023-47320 Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function o… Silverpeas 6.3.2+ Fix from $1,9502023-12-13 MEDIUM 5.4 CVE-2023-49273 Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low pr… Umbraco Cms 8.18.10 / 10.8.1+ Fix from $1,6002023-12-12 HIGH 8.8 CVE-2020-10676 In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace t… Rancher 2.6.13 / 2.7.4+ Fix from $1,9502023-12-12 HIGH 7.1 CVE-2023-6542 Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages a… Emarsys Sdk Mitigation only Fix from $1,9502023-12-12 HIGH 8.8 CVE-2023-36646 Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute p… Cryptospike No fix yet Fix from $1,9502023-12-12 HIGH 8.8 CVE-2023-48859 TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end sec… A3002ru Firmware No fix yet Fix from $1,9502023-12-06 HIGH 7.5 CVE-2023-49239 Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,9502023-12-06